Pharma AI glossary
Foundation model / GPAI
A very large model trained on broad data that many downstream applications build on.
Definition
A very large model trained on broad data that many downstream applications build on. The EU AI Act regulates these as "general-purpose AI" (GPAI) with obligations on their *providers* (transparency, copyright, systemic-risk management, applicable since August 2025); deployers building on them inherit context-specific duties. The US imposes no equivalent statutory regime; federal posture since January 2025 has favored acceleration, with NIST's Generative AI Profile as the voluntary reference. Enterprise reality: your genAI tools are almost certainly GPAI-based, so your vendor's compliance posture is part of your due diligence.
General capability, specific risk
Foundation models are large pretrained systems adapted via fine-tuning or prompting for downstream tasks. The EU AI Act treats general-purpose AI (GPAI) providers separately from deployers, but pharma deployers still inherit transparency, documentation, and systemic-risk duties when they embed GPAI in products or internal platforms.
Enterprise reality
Most pharma teams consume foundation models through vendors (Copilot, enterprise GPT, vertical SaaS). Literacy means reading vendor model cards, knowing what data leaves your boundary, and mapping fine-tuned variants to validation scope. A fine-tuned model is not the same validated object as the base model.
Frequently asked questions
Who is responsible for GPAI compliance: vendor or pharma?
Both, on different articles: providers owe documentation and some transparency; deployers owe context-of-use, literacy, and GxP controls. Contracts must close gaps, not assume the vendor’s SOC 2 covers Annex 22.
Is fine-tuning validation-friendly?
It can be if change is bounded, data is qualified, and revalidation triggers are defined. Otherwise each fine-tune becomes an uncontrolled drift event.
Where do foundation models show up in GMP operations?
Most often behind vendor SaaS: document assistants, search copilots, and vertical quality platforms for investigations, batch review, and training. Deployers still own context-of-use, data boundaries, workflow gates, and audit logs even when the base model is hosted elsewhere.
Related terms
Benchmark your AI literacy
Free 20-question assessment, eight modules, and instant scoring, built for pharma quality and manufacturing teams.
Open the Literacy CenterBrowse all terms
See the full 71-term glossary index or search interactively in the Literacy Center.
Back to glossary hub →Educational content only, not legal or regulatory advice. Regulatory guidance cited here includes drafts (FDA AI credibility guidance; EU GMP Annex 22) as of August 2026; verify against final texts before relying on them in submissions. Company-reported figures (Merck CSR timings, Sanofi results) are labeled where used. MIT's ~95% pilot figure carries its own caveat (~150 interviews, contested definitions, not peer-reviewed). Re-check sources on module finalization.